Priority reviewCritical

CVE-2022-37434

CADRA, RUGGEDCOM ROX MX5000

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).

CVSS
9.8
EPSS
17.9%
96.9% percentile
CISA KEV
Not listed
Published
2022.08.05
PRIORITY ASSESSMENT

Priority review

FIRST EPSS indicates an elevated probability of exploitation.

Known exploitationNot established by KEV
Exploit probability17.9%
Technical severityCVSS 9.8

Vulnerability overview

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).

Affected product and versions

Product
CADRA, RUGGEDCOM ROX MX5000
Affected versions
< V2511, < V2.17.0, >= V3.1.0 < V3.1.5, <= 1.2.12, 35, 36, 37, 10.0, < 15.7.1, >= 16.0 < 16.1, >= 11.0 < 11.7.1, >= 12.0.0 < 12.6.1, < 9.1, >= 3.7.31 < 3.7.34, >= 3.11.0 < 3.11.22, >= 4.3.0 < 4.3.16, >= 4.6.0 < 4.6.3
Fixed versions
15.7.1, 16.1, 11.7.1, 12.6.1, 9.1, 3.7.34, 3.11.22, 4.3.16, 4.6.3

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that CADRA, RUGGEDCOM ROX MX5000 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-120, CWE-787
CVE-2022-37434 — CADRA, RUGGEDCOM ROX MX5000 | SECUFOCUS NOW